Cyber Incident Victim: Uber Freight
Timeline
Summary
Uber Freight is under investigation after the Helix hacking group claimed to have exfiltrated mailboxes, cloud storage drives, accounts payable files, and dispatch documents from its systems, with some email correspondence appearing online. The company said its operations were unaffected and systems remained normal while it reviewed the allegations. Helix, which Google links to the broader UNC6671 collective, relies on social engineering such as voice phishing to obtain credentials and has reportedly amassed at least $10.6 million in ransom payments.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 2 actors | Available to members | Available to members |
Description
A hacking and extortion group known as Helix claimed responsibility for a cyberattack and data breach at Uber Freight, the logistics subsidiary of the ridesharing company, according to a report first published by Reuters and later covered by TechCrunch on August 12 2026. A spokesperson for Uber Freight told Reuters that the incident had no effect on its business operations and that its systems were running normally, although the company did not immediately respond to TechCrunch’s requests for comment. In a post on its data leak site, Helix asserted that it had exfiltrated mailboxes, cloud storage drives, accounts payable files, and dispatch documents from Uber Freight’s environment. TechCrunch reviewed some of the leaked files and observed what appeared to be email correspondence between Uber Freight and several of its customers, noting that the documents seemed to be dated around mid‑June 2026, but the outlet could not immediately verify their authenticity. Uber Freight has not publicly stated whether it received any direct communication from the hackers or whether it paid a ransom demand.

Helix is identified by Google as part of a broader threat cluster tracked as UNC6671, a collective that has targeted transportation firms, financial institutions, and private equity companies throughout 2026. The group is known for employing social engineering techniques, particularly voice phishing, in which attackers call IT help desks and request password resets to gain initial access to victim networks. Security researchers have noted that while these tactics are relatively crude, they have proven effective at tricking employees into divulging credentials that allow attackers to infiltrate cloud environments and exfiltrate large volumes of data. Google’s analysis of the gang’s Bitcoin wallets indicated that Helix had received at least $10.6 million in ransom payments between January and May 2026, underscoring the financial motivation behind its campaigns.
As of the latest available information, Uber Freight has not confirmed receipt of any ransom note from Helix, nor has it disclosed whether any payment was made. The company’s spokesperson emphasized that business operations remained unaffected and that systems continued to function normally, but no further details about internal investigations, containment measures, or potential data loss have been provided publicly. The incident adds Uber Freight to a growing list of organizations reportedly targeted by Helix/UNC6671 in a series of attacks that rely heavily on credential‑theft via voice‑based social engineering.
